Executive brief
A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure components used to manage enterprise resource planning (ERP) software. A low-privileged user could exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized changes to business records, and disruption of critical business operations.
Technical details
A vulnerability in the Business Logic Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) allows for improper privilege management and authentication bypass. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to achieve a complete takeover of the JD Edwards EnterpriseOne Tools environment, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CWE-269, CWE-287, and CWE-306. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date